Community Link Pro Login.CGI File Parameter Remote Command Execution Vulnerability
BID:14097
Info
Community Link Pro Login.CGI File Parameter Remote Command Execution Vulnerability
| Bugtraq ID: | 14097 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 29 2005 12:00AM |
| Updated: | Jun 29 2005 12:00AM |
| Credit: | Discovery is credited to mozako <[email protected]>. |
| Vulnerable: |
Community Link Pro Login.cgi |
| Not Vulnerable: | |
Discussion
Community Link Pro Login.CGI File Parameter Remote Command Execution Vulnerability
Community Link Pro is prone to a remote arbitrary command execution vulnerability. This issue presents itself due to insufficient sanitization of user-supplied data.
Due to this, an attacker can prefix arbitrary commands with the '|' character and have them executed in the context of the server.
Community Link Pro is prone to a remote arbitrary command execution vulnerability. This issue presents itself due to insufficient sanitization of user-supplied data.
Due to this, an attacker can prefix arbitrary commands with the '|' character and have them executed in the context of the server.
Exploit / POC
Community Link Pro Login.CGI File Parameter Remote Command Execution Vulnerability
An exploit is not required.
The following proof of concept is available:
http://www.example.com/app/webeditor/login.cgi?username=&command=simple&do=edit&password=&file=|uname -a; id|
An exploit is not required.
The following proof of concept is available:
http://www.example.com/app/webeditor/login.cgi?username=&command=simple&do=edit&password=&file=|uname -a; id|
Solution / Fix
Community Link Pro Login.CGI File Parameter Remote Command Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Community Link Pro Login.CGI File Parameter Remote Command Execution Vulnerability
References:
References: